|
|||||||||||
|
RE: Did IDSes detect the SQL worm?
From: Gonzalez, Albert <albert.gonzalez(at)eds.com>
Date: Wed Jan 29 2003 - 14:15:14 EST
Cheers! Alberto Gonzalez
-----Original Message-----
Much has been made about the fact that the vulnerability exploited by the MS-SQL worm has been known about for six months. So not only should users have been aware of it, but IDS vendors should have been aware of it. Here is my question: Other than an IDS reporting an unusual amount of traffic to port 1434, did any report the specific nature of the attack? In other words, did any IDS report that the packet appears to attack a vulnerability identified by CAN-2002-0649? Thanks, Todd Received on Fri Jan 31 11:07:22 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:08 EDT |
||||||||||
|
|||||||||||